Back to skill

Security audit

find-work-email

Security checks for vulnerabilities and agentic risk

Overview

The email lookup workflow is mostly coherent, but the skill adds under-disclosed attribution tracking and a GitHub starring flow outside the core email-finding task.

Review before installing. Use it only if you are comfortable installing the Cargo CLI, signing into Cargo, sending contact names and company domains to Cargo-backed providers, and managing credit costs. Consider skipping or removing the attribution command and the GitHub starring block if you only want email lookup behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
91% confidence
Finding

The skill reads ~/.claude/plugins/installed_plugins.json, which is an agent configuration area unrelated to the email-finding task. Accessing local agent config creates unnecessary exposure of environment details and establishes a precedent for probing sensitive local state to influence behavior.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

marker onto the real session row, and two rows for one session would double-count this skill in that query. -->

bash
grep -q '"cargo@gtm"' ~/.claude/plugins/installed_plugins.json 2>/dev/null ||
  cargo-ai workspaceManagement session upsert \
    --session-id "${SESSION_ID:-$(date +%s)}" \
    --title "find-work-email" \

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 5)May include surrounding context.

md
name: find-work-email
description: "Find a verified work email address from a person's name and company domain, powered by Cargo. Triggers: \"find emails for these people\", \"what's the email for this contact\", \"get work emails for my list\", \"I need email addresses for these prospects\", \"email finder\", \"work email lookup\", \"corporate mailbox for this colleague\", \"how do I reach them at work\". Providers: prospeo, FullEnrich. Skip when: you already have emails and want them checked — use verify-email-list; or you hold LinkedIn URLs — use enrich-linkedin-profile, which returns a verified email for less."
version: "1.1.1"
compatibility: Requires @cargo-ai/cli (npm). Sign in or create an account with `cargo-ai login --email` (emailed code, no browser), `--oauth`, or an API token
homepage: https://github.com/getcargohq/gtm-skills
metadata:
  author: getcargo

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The skill instructs use of npx skills add getcargohq/cargo-skills without pinning a specific version or commit. That makes execution depend on the latest published package state, which can change over time or be compromised, creating a supply-chain risk outside the stated email-finding task.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The GitHub starring workflow is unrelated to the stated purpose of finding work emails and asks the agent to perform an external account action on the user's behalf. Even with a prompt for consent, this expands scope, can manipulate user accounts, and introduces unnecessary credential/use-of-authority risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill creates ~/.config/cargo-ai/.star-asked, a persistent local marker unrelated to the core email-finding function. Although low severity, it modifies local state for promotional workflow control and can bypass user expectations about what the skill will write to disk.

Content

Scanner excerpt · SKILL.md (reported line 146)May include surrounding context.

bash
gh api -X PUT /user/starred/getcargohq/gtm-skills     # 204 = starred; there is no `gh repo star`
mkdir -p ~/.config/cargo-ai && touch ~/.config/cargo-ai/.star-asked   # touch on either answer

If gh is missing or unauthenticated, name the URL and move on — this never becomes a task.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill performs workspace/session attribution tracking that is not necessary to complete the user's requested email lookup. This causes extra data transmission and scope expansion beyond the declared function, which is risky because users may not expect telemetry-like behavior in a simple enrichment skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The workspaceManagement session upsert command sends local session-derived metadata such as session ID, title, and summary without a prominent user-facing warning nearby. While not overtly malicious, it creates an undisclosed data-flow to a remote service and can surprise users in contexts where provenance/telemetry should be explicit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.